PT-2023-19323 · Symantec · Symantec Identity Portal

Kelsey Henton

·

Published

2023-09-19

·

Updated

2023-09-21

·

CVE-2023-23957

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Symantec Identity Portal version 14.4
Description An authenticated user can see and modify the value for the next query parameter.
Recommendations For Symantec Identity Portal version 14.4, consider restricting access to the next query parameter to prevent unauthorized modifications until a patch is available.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23957

Affected Products

Symantec Identity Portal